Quick Answer: There is no active CMMC certification deadline. On July 13, 2026, the Department of War suspended CMMC Phase 2, which would have required third-party Level 2 assessments starting November 10, 2026, and Phases 3 and 4 are on hold with it. Phase 1 did not change. If your contract carries CMMC clauses today, you still owe a self-assessment, a current SPRS score, and an annual affirmation.
If your organization holds Department of Defense contracts, or plans to bid on them, the compliance picture shifted in July 2026 and has not settled since.
The short version is that the certification deadline you were working toward is gone. The obligations underneath it are not.
That distinction carries most of the weight here. Contractors reading the pause as a cancellation are exposed right now, in ways that have nothing to do with a certification date. Below is what was suspended, what is still enforced, and what to do with the time you have been handed.
(Updated August 18th, 2026)
Two things happened at once, and conflating them is the most common mistake right now.
A verification step was suspended. The underlying security obligations were not touched.
|
Paused for Now |
Still Required Today |
|---|---|
|
Mandatory Phase 2 third-party (C3PAO) assessments for Level 2 |
NIST SP 800-171, all 110 controls across 14 domains |
|
Level 3 assessments under Phase 3 |
DFARS 252.204-7012 safeguarding and 72-hour incident reporting |
|
New Level 2 and Level 3 clauses in solicitations and contracts |
A current, accurate SPRS score and annual affirmation |
|
All remaining rollout milestones, held in abeyance |
FAR 52.204-21 basic safeguarding for FCI |
|
FedRAMP Moderate equivalent cloud for CUI, and flow-down to subcontractors |
No. There is no active CMMC certification deadline. The Department of War suspended CMMC Phase 2 on July 13, 2026, removing the November 10, 2026 requirement for third-party Level 2 assessments. Phase 1 self-assessment obligations continue exactly as before.
That is the whole answer, and it is worth stating plainly because a lot of coverage has muddied it.
What the suspension did not do matters more than what it did. The CMMC Program rule at 32 CFR Part 170 was not repealed. The DFARS was not amended. No regulation changed.
A memorandum directs how the government exercises its discretion. It does not rewrite the law underneath. Every contractual cybersecurity duty you had on July 12 you still had on July 14.
If you take one thing from this article: the pause lifted a verification step. It did not lift the obligation to protect covered defense information.
On July 13, 2026, two memoranda were issued.
The Chief Information Officer directed the immediate suspension of Phase 2. A companion memorandum from the Under Secretary of Defense for Acquisition and Sustainment told contracting officers to amend active solicitations and contracts, stripping Level 2 and Level 3 assessment requirements.
A new CMMC Reform Task Force was stood up at the same time, with 60 days to deliver a top-to-bottom review of the program. Recommendations are expected in early to mid September 2026.
The stated reasons were capacity and cost, and both are worth understanding because they shape what comes next.
The department also issued a request for information asking industry which NIST 800-171 controls deliver genuine risk reduction. Responses closed on August 14, 2026. You can follow official program status on the DoD CIO CMMC program page.
Read that question carefully. It suggests a program being reshaped around effectiveness, not one being abandoned.
The scope did not narrow. If you handle federal data, you are still in it.
Handling Federal Contract Information only, meaning information needed to perform a contract but not for public release, puts you at CMMC Level 1. Handling Controlled Unclassified Information puts you at CMMC Level 2 or above.
If you are unsure which applies, our guides on who needs CMMC compliance and CMMC Level 1 versus Level 2 walk through the distinction.
This applies to prime contractors and subcontractors alike. There is no exemption based on company size, and prime contractors continue to screen their supply chains on readiness regardless of what the department does with the rollout calendar.
Phase 1 has been in force since November 10, 2025.
Applicable solicitations still carry a requirement for a CMMC self assessment at Level 1 or Level 2, and a CMMC Status is still a condition of award on those contracts. For a refresher on how the tiers differ, see our breakdown of the levels of CMMC.
Nothing about the July suspension touched this. Contractors who stopped their self-assessment work in July have created a live contract eligibility problem for themselves.
DFARS 252.204-7012 has appeared in Department of Defense contracts since 2016. It predates CMMC by years, it was never dependent on CMMC, and it survived the suspension untouched.
If your contract contains this clause, four duties apply today.
CMMC was only ever the mechanism for checking whether you had done this. Removing the check does not remove the requirement, and it does not remove the liability attached to it.
Want the full breakdown in one place? Fill the form below to download the CMMC Phase 2 Pause Brief, covering what changed, what did not, and the specific steps worth taking during the review period.
Here is the part that most contractors have not worked through.
With third-party assessments paused, the government leans harder on what you tell it about yourself. Your Supplier Performance Risk System score and your annual affirmation become the primary record of your compliance.
An inflated SPRS score is not a paperwork gap. It is a statement to the federal government, and an unsupported one is a potential false claim.
The Defense Industrial Base Cybersecurity Assessment Center can still assess your environment at any time and compare its findings to the number you posted. That has not been suspended either.
In June 2026, a Navy contractor settled with the Department of Justice for 507,144 dollars.
The company had self-reported a perfect score of 110. A subsequent assessment of the same environment scored it at negative 170. The SPRS scale runs from negative 203 to 110, so that is close to the bottom of the range.
The settlement was not about failing an audit. There was no audit to fail. It was about the distance between what the company claimed and what was actually there.
That case is not isolated. Department of Justice cyber-fraud recoveries reached 52 million dollars across nine settlements in FY2025, part of a record 6.8 billion dollars in False Claims Act recoveries overall. Cyber-fraud resolutions have more than tripled in two consecutive years.
The enforcement engine never paused. If anything, less audit and more self-attestation moves the exposure onto you.
A specific question is coming up repeatedly right now. Contractors midway through a GCC High migration, budgeted against a November 2026 assessment, are asking whether to pause the spend.
Usually the answer is no, and the reasoning is worth setting out.
Pausing that work does not defer your exposure. It creates exposure immediately, against requirements that are already live, while removing the assessment that would have caught the problem early.
The review period is genuinely useful if you treat it as working time rather than waiting time.
The competitive logic is simple enough. Firms treating the pause as a stop will be starting over in the autumn. Firms treating it as a build window will be ready.
The difficulty has changed shape. It used to be technical. Now it is interpretive, which is harder to staff for.
This is the work BEMO takes on:
All this is run by a dedicated compliance team rather than added to an already stretched IT function.
Our compliance-readiness security tier is built around exactly this problem.
Cost depends on your required level, your current security maturity, and the size of your CUI environment.
Level 1 costs are mostly staff time and documentation. Level 2 varies considerably, driven by how much of the 110 controls you already meet and whether a tenant migration is involved. Organizations with mature controls already in place face a much smaller gap than those starting from a standard commercial environment.
For a fuller breakdown of what drives the number, see our guide to how much CMMC certification costs. For a scenario-based estimate against your actual headcount, licensing, and support model, the CMMC Level 2 with GCC High cost calculator gives a far more useful figure than any published range.
The certification deadline is gone. The security obligations are not.
That is the whole situation in two sentences. The contractors who act on it will be in a stronger position in September than the ones who waited to be told what to do.
Focus on building a security program so robust that successful assessments become the natural outcome of your daily operations.
Compliance is the byproduct of good security. A certificate confirms you met a standard in one day. It does not confirm you are protected tomorrow.
Your one next step: get an honest read on where you stand across all 110 controls, and a plan that holds up whatever the task force recommends. Book a meeting with BEMO to discuss your specific compliance needs.
Phase 1 has been in effect since November 10, 2025 and still applies. Phase 2, originally set for November 10, 2026, was suspended on July 13, 2026, along with the later phases. No replacement dates have been published.
Yes, where your contract requires it. Phase 1 self-assessment requirements still appear in applicable solicitations, and a CMMC Status remains a condition of award. Only the third-party assessment requirement was suspended.
It already has been. The CMMC Reform Task Force is reviewing the program, and recommendations are expected in early to mid September 2026. Whether Phase 2 returns on the original terms is not yet known.
No. The program rule at 32 CFR Part 170 remains in force and the DFARS was not amended. This was a policy suspension of specific requirements, not a repeal. C3PAO assessments are also continuing for organizations that want them.
Annually. An affirming official must confirm continued compliance each year and post it to SPRS, alongside a current self-assessment score. The suspension did not change this.